Hi team, according to some news, an apache log4j v...
# feedback-and-requests
y
Hi team, according to some news, an apache log4j vulnerability was founded. The affected versions are 2.0 <= Apache log4j2 <= 2.14.1. Airbyte uses one of them. So, it would be great to upgrade log4j immediately. • https://www.cyberkendra.com/2021/12/worst-log4j-rce-zeroday-dropped-on.htmlhttps://www.spigotmc.org/threads/security-releases-%E2%80%94-1-8-8%E2%80%931-18.537204/
u
@Lake Mossman were you doing a release?
u
u
u
@Jared Rhizor (Airbyte) Thank you for quickly fixing it!
u
Sorry I was afk, I was planning to do a release but it looks like you took care of it. Thanks!
u
Yay!!
u
Is there any security advisory or some blog post/update published for on-prem users, that they can see which versions are affected and what to upgrade to?
u
The log4j PR was merged and release as part of Airbyte `0.33.8`: https://github.com/airbytehq/airbyte/pull/8688
u
Thanks a lot!
u
Hi, it would be good to upgrade log4j2 to 2.16.0. The version contains more secure implementation. https://github.com/apache/logging-log4j2/releases/tag/rel%2F2.16.0
m
Already available in 0.33.12-alpha!